Hacker News new | ask | show | jobs
by goodlinks 1609 days ago
Are there best practice process diagrams to support the correct usage of these with b2c services?

how should the initial verifiacation happen? what happens when i loose/corrupt/break the device? should this represent me as a human or the keys to an account? - should a human hold the permissions ultimately (if so how to i override a key?)